Textpattern 4.8.4 is affected by cross-site scripting (XSS) in the Body parameter.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://textpattern.com | product |
https://www.textpattern.co/demo | product |
https://riteshgohil-25.medium.com/textpattern-4-8-4-is-affected-by-cross-site-scripting-xss-in-the-body-parameter-b9a3d7da2a88 | third party advisory exploit |